@Nasdak
The topologies in the screenshot are really confusing.
If you want to avoid the double NAT, you trust your friend and he is using a pfSense to provide an internet connection for you then :
You may configure AX20 in AP mode (Case 1) and have a common local network with your friend's pfSense within the 172.30.0.0/24 subnet.
For that purpose you can set AX20 LAN IP static 172.30.0.254 (for example).
If you don't trust your friend that much or you want to have a separate LAN than your fiend's pfSense I am afraid that double NAT is inevitable and you should choose the first option.
Bare in mind that in both cases your internet traffic will go trough your friend's pfSense and potentially can be sniffed/monitored.